Executive brief
The Apollo Pharmacy Blood Glucose Monitoring System (APG-01 BT) is a medical device used by patients to track blood sugar levels. A security flaw allows an attacker within Bluetooth range to intercept wireless communications and steal sensitive health data, including glucose readings. This could lead to a significant breach of patient privacy and the exposure of protected health information.
Technical details
The Apollo Pharmacy Blood Glucose Monitoring System (Model No. APG-01 BT) version 0x0110_v1.1.0 is vulnerable to cleartext transmission of sensitive information (CWE-319). Due to a lack of encryption or improper implementation of the Bluetooth Low Energy (BLE) stack, an attacker within physical proximity (BLE range) can passively sniff wireless traffic. This allows for the interception of sensitive health-related data, specifically glucose measurement values, without requiring authentication or user interaction. As of the advisory date, the vendor has not provided a patch, and users are advised to follow general Bluetooth security best practices.
Affected products
- Apollo Pharmacy Blood Glucose Monitoring System (Model No. APG-01 BT) 0x0110_v1.1.0
Timeline
- 2026-06-18: advisory: CISA published ICSMA-26-169-01
- 2026-06-19: disclosed: CVE-2026-50034 published to NVD